# Restricting user access to subsets of DICOM files

**URL:** https://discourse.orthanc-server.org/t/restricting-user-access-to-subsets-of-dicom-files/2593
**Category:** Google Groups archive
**Created:** [August 26, 2021, 4:16pm UTC](https://discourse.orthanc-server.org/t/restricting-user-access-to-subsets-of-dicom-files/2593 "2021-08-26T16:16:25Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![Normand\_Robert](https://discourse.orthanc-server.org/letter_avatar_proxy/v4/letter/n/b4bc9f/32.png) [@Normand\_Robert](https://discourse.orthanc-server.org/u/Normand_Robert)
#### Post date: [August 26, 2021, 4:16pm UTC](https://discourse.orthanc-server.org/t/restricting-user-access-to-subsets-of-dicom-files/2593/1 "2021-08-26T16:16:25Z")

</div>

I am trying to think of ways to restrict user access to subsets of DICOM files depending on the REB/IRB users are associated with. Apart from the obvious solution of running multiple orthanc instances by creating distinct init.d service files is there something else I can do? Can storage be shared to avoid file duplication if two people have interest in the same file?

---

<div class="post-metadata">

### Author: ![salimkanoun](https://discourse.orthanc-server.org/letter_avatar_proxy/v4/letter/s/6de8d8/32.png) [@salimkanoun](https://discourse.orthanc-server.org/u/salimkanoun)
#### Post date: [August 26, 2021, 4:37pm UTC](https://discourse.orthanc-server.org/t/restricting-user-access-to-subsets-of-dicom-files/2593/2 "2021-08-26T16:37:44Z")

</div>

We tried to implement such a feature in OrthancToolsJS  
[https://github.com/salimkanoun/Orthanc-Tools-JS](https://github.com/salimkanoun/Orthanc-Tools-JS)

It’s partly done but the projet is going for a pause, we will release the 0.7.0 version and then will wait for funding to continue.

Technically the idea is to make an application that will implement your logic and deal with orthanc.

Best regards,

Salim

---

<div class="post-metadata">

### Author: ![Normand\_Robert](https://discourse.orthanc-server.org/letter_avatar_proxy/v4/letter/n/b4bc9f/32.png) [@Normand\_Robert](https://discourse.orthanc-server.org/u/Normand_Robert)
#### Post date: [August 26, 2021, 6:19pm UTC](https://discourse.orthanc-server.org/t/restricting-user-access-to-subsets-of-dicom-files/2593/3 "2021-08-26T18:19:11Z")

</div>

I am wondering if one could use a LUA script for example to check the calling AE title to control access if using just one orthanc instance. The calling AE title would become a sort of password.

---

<div class="post-metadata">

### Author: ![jodogne](https://discourse.orthanc-server.org/user_avatar/discourse.orthanc-server.org/jodogne/32/1511_2.png) [@jodogne](https://discourse.orthanc-server.org/u/jodogne)
#### Post date: [August 27, 2021, 5:51am UTC](https://discourse.orthanc-server.org/t/restricting-user-access-to-subsets-of-dicom-files/2593/4 "2021-08-27T05:51:30Z")

</div>

You can specify what are the permissions for each calling AET by tuning the “DicomModalities” configuration option:

[https://hg.orthanc-server.com/orthanc/file/Orthanc-1.9.6/OrthancServer/Resources/Configuration.json#l306](https://hg.orthanc-server.com/orthanc/file/Orthanc-1.9.6/OrthancServer/Resources/Configuration.json#l306)

Depending on your scenario, you could be interested in setting “DicomAlwaysAllowStore” to “false”.

---

<div class="post-metadata">

### Author: ![Normand\_Robert](https://discourse.orthanc-server.org/letter_avatar_proxy/v4/letter/n/b4bc9f/32.png) [@Normand\_Robert](https://discourse.orthanc-server.org/u/Normand_Robert)
#### Post date: [August 27, 2021, 2:16pm UTC](https://discourse.orthanc-server.org/t/restricting-user-access-to-subsets-of-dicom-files/2593/5 "2021-08-27T14:16:56Z")

</div>

Merci Sébastien.  
I wanted something more granular and dynamic. I wanted to restrict access of different users to different and possibly overlapping subsets of studies. I wanted to avoid running multiple servers to achieve this aim and was thinking of ways to do this with one server possibly distinguishing users by AETs and intercepting associations. ¿C’est fou comme idée?

---

<div class="post-metadata">

### Author: ![Alain\_Mazy1](https://discourse.orthanc-server.org/letter_avatar_proxy/v4/letter/a/839c29/32.png) [@Alain\_Mazy1](https://discourse.orthanc-server.org/u/Alain_Mazy1)
#### Post date: [August 27, 2021, 2:41pm UTC](https://discourse.orthanc-server.org/t/restricting-user-access-to-subsets-of-dicom-files/2593/6 "2021-08-27T14:41:47Z")

</div>

Hi Robert,

Pas si fou comme idée !

You can probably achieve that with some python scripting by filtering the results of C-Find commands and preventing C-Move commands based on the issuer AET:

[https://book.orthanc-server.com/plugins/python.html#handling-dicom-scp-requests-new-in-3-2](https://book.orthanc-server.com/plugins/python.html#handling-dicom-scp-requests-new-in-3-2)

HTH

Alain.

---

<div class="post-metadata">

### Author: ![Carlos123](https://discourse.orthanc-server.org/letter_avatar_proxy/v4/letter/c/f17d59/32.png) [@Carlos123](https://discourse.orthanc-server.org/u/Carlos123)
#### Post date: [February 14, 2025, 2:20pm UTC](https://discourse.orthanc-server.org/t/restricting-user-access-to-subsets-of-dicom-files/2593/7 "2025-02-14T14:20:08Z")

</div>

> [@Normand\_Robert](#):
>
> I am trying to think of ways to restrict user access to subsets of DICOM files depending on the REB/IRB users are associated with. Apart from the obvious solution of running multiple orthanc instances by creating distinct init.d service files is there something else I can do? Can storage be shared to avoid file duplication if two people have interest in the same file?

Any update on this project?? It will be a GREAT Add to Orthanc
